Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian 10 Buster: DLA-3376-1 Critical: Svgpp Library Security Issues

debian lts
Calendar Grey April 1, 2023
Dist Debian Esm H88
Strengthen svgpp by addressing multiple significant security flaws identified in the handling of SVG data.
Multiple security issues were discovered in svgpp: a C++ library for parsing and rendering Scalable Vector Graphics (SVG) files

Summary

CVE-2021-44960
The XMLDocument::getRoot function in the renderDocument function handled the
XMLDocument object improperly. Specifically, it returned a null pointer
prematurely at the second if statement, resulting in a null pointer
reference behind the renderDocument function.

CVE-2019-6245 and CVE-2019-6247:
issues were discovered in Anti-Grain Geometry (AGG) within the function
agg::cell_aa::not_equal. Since svgpp is a header-only library, the issue is
only transitive in theory. As a result, only a dependency version hardening
has been added to the control file.

For Debian 10 buster, these problems have been fixed in version
1.2.3+dfsg1-6+deb10u1.

We recommend that you upgrade your svgpp packages.

For the detailed security status of svgpp please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/svgpp

Further information about Debian LTS security advisories, how to apply

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: svgpp
Version: 1.2.3+dfsg1-6+deb10u1
CVE ID: CVE-2019-6245 CVE-2019-6247 CVE-2021-44960

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here